QuestionQ606
Information Security GovernanceInternal audit has identified several information-security issues that do not comply with regulatory requirements. What should the information security manager do FIRST?
- A Create a security exception
- B Assess the risk to business operations
- C Perform a vulnerability assessment
- D Perform a gap analysis to determine needed resources
Community Discussion